<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Zenq | Blog</title><description/><link>https://zenq.io/</link><language>en</language><item><title>How Zenq Keeps Your Manager Notes Private</title><link>https://zenq.io/blog/how-zenq-keeps-your-manager-notes-private/</link><guid isPermaLink="true">https://zenq.io/blog/how-zenq-keeps-your-manager-notes-private/</guid><description>Zenq is private by default: direct reports and private notes are visible only to you, even on Team workspaces. Here&apos;s how our access model works across projects, roles, and the AI assistant.

</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Manager context is sensitive. It includes half-formed thoughts, personal situations, early signals, and decisions you’re still shaping. Zenq is built around a simple idea: you should be able to capture that context without worrying it will become visible to the wrong people.&lt;/p&gt;
&lt;p&gt;This post explains what “private by default” means in Zenq today, how access works inside a workspace, and how we enforce it across the app, database, and AI assistant.&lt;/p&gt;
&lt;article&gt; &lt;p&gt;  &lt;span&gt;TL;DR&lt;/span&gt; &lt;/p&gt; &lt;div&gt;&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Direct reports are always private&lt;/strong&gt; in Zenq.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Your private notes are visible only to you&lt;/strong&gt;, even on a Team workspace.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Projects can be private or shared&lt;/strong&gt; within your workspace.&lt;/li&gt;
&lt;li&gt;Access control is enforced on &lt;strong&gt;both the application and database levels&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;AI assistant only accesses what you can access&lt;/strong&gt; (enforced the same way).&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt; &lt;/article&gt; 
&lt;div&gt;&lt;h2 id=&quot;why-manager-notes-need-stronger-privacy&quot;&gt;Why manager notes need stronger privacy&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;Most work tools are designed for sharing. That’s great for project docs - but it’s the opposite of what you want for many manager notes.&lt;/p&gt;
&lt;p&gt;Manager notes often include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;sensitive context you’d never put in a shared doc&lt;/li&gt;
&lt;li&gt;coaching observations and follow-ups&lt;/li&gt;
&lt;li&gt;personal circumstances shared in confidence&lt;/li&gt;
&lt;li&gt;decisions and tradeoffs that need time to mature&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Zenq is not an HR system and not a performance tracking tool. It’s a private workspace that helps you stay on top of context - without turning your notes into something you feel you need to “sanitize.”&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;what-private-means-in-zenq&quot;&gt;What “private” means in Zenq&lt;/h2&gt;&lt;/div&gt;
&lt;div&gt;&lt;h3 id=&quot;direct-reports-are-always-private&quot;&gt;Direct reports are always private&lt;/h3&gt;&lt;/div&gt;
&lt;p&gt;Every direct report you add in Zenq is private to you. That includes their page, your notes, and the context you attach to them.&lt;/p&gt;
&lt;p&gt;Even if you’re on a Team plan, direct reports are not a workspace-shared resource. They’re your personal manager space.&lt;/p&gt;
&lt;div&gt;&lt;h3 id=&quot;projects-can-be-private-or-shared&quot;&gt;Projects can be private or shared&lt;/h3&gt;&lt;/div&gt;
&lt;div&gt;&lt;img src=&quot;https://zenq.io/_astro/privacy-control.ChhLfpDo_1OAMWI.webp&quot; alt=&quot;Zenq privacy control&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; fetchpriority=&quot;auto&quot; width=&quot;1200&quot; height=&quot;308&quot;&gt;&lt;/div&gt;
&lt;p&gt;Projects are different: some are personal “manager context” projects, and some are shared initiatives where it’s helpful for your workspace to collaborate.&lt;/p&gt;
&lt;p&gt;In Zenq, a project can be:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Private:&lt;/strong&gt; visible only to you&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shared:&lt;/strong&gt; visible within the workspace&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This gives you flexibility: keep your own manager context private, and share only what’s meant to be shared.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;who-can-see-what-in-a-zenq-workspace&quot;&gt;Who can see what in a Zenq workspace&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;Zenq workspaces have two roles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Admin&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Member&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div&gt;&lt;img src=&quot;https://zenq.io/_astro/workspace-members.BjuAYVfM_VbyP0.webp&quot; alt=&quot;Zenq workspace mamebers management&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; fetchpriority=&quot;auto&quot; width=&quot;1200&quot; height=&quot;513&quot;&gt;&lt;/div&gt;
&lt;p&gt;Both roles have the same access to content. The only difference is that &lt;strong&gt;Admins can manage billing and workspace members&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Here’s the practical “who sees what”:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Direct reports:&lt;/strong&gt; only you (always private)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Private notes:&lt;/strong&gt; only you&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Private projects:&lt;/strong&gt; only you&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Shared projects:&lt;/strong&gt; visible within the workspace (to Admins and Members)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you’re in a Team workspace, that doesn’t grant anyone extra access to your private manager context. It just enables a shared space for projects that you explicitly choose to share.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;how-zenq-enforces-access-control&quot;&gt;How Zenq enforces access control&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;Privacy isn’t a UI feature. It has to be enforced in a way that holds up even when things get complex - new features, edge cases, future integrations, and honest mistakes.&lt;/p&gt;
&lt;p&gt;Zenq enforces access control on &lt;strong&gt;two levels&lt;/strong&gt;:&lt;/p&gt;
&lt;div&gt;&lt;h3 id=&quot;1-application-level-checks&quot;&gt;1) Application-level checks&lt;/h3&gt;&lt;/div&gt;
&lt;p&gt;Every request is evaluated against:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the authenticated user&lt;/li&gt;
&lt;li&gt;the workspace context&lt;/li&gt;
&lt;li&gt;the requested resource (direct report, project, note, etc.)&lt;/li&gt;
&lt;li&gt;the resource’s visibility (private vs shared)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This ensures that the app itself never “accidentally” returns data outside the user’s permissions.&lt;/p&gt;
&lt;div&gt;&lt;h3 id=&quot;2-database-level-enforcement&quot;&gt;2) Database-level enforcement&lt;/h3&gt;&lt;/div&gt;
&lt;p&gt;We also enforce access control at the database level. That way, even if a bug slipped into application logic, the database still acts as a second line of defense.&lt;/p&gt;
&lt;p&gt;This is a key part of “secure by design”: trust is built through redundancy.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;ai-assistant-access-same-permissions-as-you&quot;&gt;AI assistant access: same permissions as you&lt;/h2&gt;&lt;/div&gt;
&lt;div&gt;&lt;img src=&quot;https://zenq.io/_astro/assistant-no-access.B13f3PFd_1eYwMh.webp&quot; alt=&quot;Zenq Assistant has the same access as you&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; fetchpriority=&quot;auto&quot; width=&quot;1200&quot; height=&quot;1005&quot;&gt;&lt;/div&gt;
&lt;p&gt;Zenq’s AI assistant is useful only if it can work with your real context - but it should never become a shortcut around permissions.&lt;/p&gt;
&lt;p&gt;In Zenq:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;the AI assistant can access &lt;strong&gt;only the data you can access&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;this is &lt;strong&gt;enforced&lt;/strong&gt; (not “best effort”)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;if something is private to you, the assistant can use it when &lt;em&gt;you&lt;/em&gt; ask&lt;/li&gt;
&lt;li&gt;if a project is shared, it can help with that shared context too&lt;/li&gt;
&lt;li&gt;if you can’t see something, the assistant can’t see it either&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This keeps AI helpful while preserving the same privacy boundaries as the rest of the product.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;what-zenq-does-not-do&quot;&gt;What Zenq does not do&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;To be explicit, Zenq does &lt;strong&gt;not&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;expose your private notes to workspace Admins&lt;/li&gt;
&lt;li&gt;automatically share direct report context into shared project spaces&lt;/li&gt;
&lt;li&gt;act as an HR system or employee surveillance tool&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Zenq is built for managers who want to be organized without feeling observed.&lt;/p&gt;
&lt;div&gt;&lt;h2 id=&quot;privacy-isnt-a-checkbox&quot;&gt;Privacy isn’t a checkbox&lt;/h2&gt;&lt;/div&gt;
&lt;p&gt;You’ll see lots of products claim “secure” with a list of certifications and buzzwords. Zenq’s approach is simpler: clear boundaries, enforced consistently, and designed around the reality of manager work.&lt;/p&gt;
&lt;p&gt;If you have questions about privacy, security, or how Zenq fits your team’s workflow, reach out - we’ll answer directly and transparently.&lt;/p&gt;
&lt;a href=&quot;https://app.zenq.io&quot;&gt;Get started with Zenq for free →&lt;/a&gt;</content:encoded><category>privacy</category><category>security</category><category>product</category><category>AI Assistant</category></item></channel></rss>